Across Solana Relayer Attack Drained $4.5M - No User Lost a Cent

NewsFri, 24 Jul 2026 18:40:43 UTC2 hours ago
Across Solana Relayer Attack Drained $4.5M - No User Lost a Cent

A missing eight-byte check in an offchain code file handed an attacker a window to drain roughly $4.5 million from a Risk Labs-operated relayer on July 17, 2026 — yet every user of the Across protocol walked away without losing a cent. The Across Solana relayer attack exposed a narrow but consequential gap between what a blockchain sees and what offchain software chooses to trust.

Key takeaways

  • On July 17, 2026, an attacker exploited a bug in Risk Labs’ offchain Solana relayer by forging deposit events that never existed on-chain.
  • No user funds were lost or at risk; every genuine transfer was completed or refunded the same day.
  • Risk Labs absorbed approximately $4.5 million gross in relayer capital, with a net loss under $4 million and shrinking as recovery continues.
  • The attacker submitted 1,627 forged deposits across 18 destination chains totaling roughly $41.7 million in face value; the relayer filled 581 of them before Solana was disabled.
  • Solana service was restored in approximately 12 hours via fallback CCTP routing; law enforcement and SEAL 911 are actively involved in recovery efforts.

Details of the Across Solana Relayer Attack

The incident unfolded inside a narrow technical seam between Solana’s onchain programs and the offchain software Risk Labs used to read them. No funds moved on-chain during the attack. No state changed. The blockchain itself behaved perfectly — but the software watching it did not.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related